JWA, JWS, JWE, JWT, JWK, JWKS for Node.js, Browser, Cloudflare Workers, Deno, Bun, and other Web-interoperable runtimes
100%
Total Score
100
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-584205 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. jose is vulnerable to Improper Authentication in versions 4.14.0 - 6.2.4. | 4.14.0 - 6.2.4 | Low |
CVE-2024-28176 jose is vulnerable to Uncontrolled Resource Consumption in versions 3.0.0 - 4.15.4 and 0.0.0 - 2.0.7. | 0.0.0 - 2.0.73.0.0 - 4.15.4 | Medium |
CVE-2022-36083 jose is vulnerable to Uncontrolled Resource Consumption in versions 1.0.0 - 1.28.1, 2.0.0 - 2.0.5, 3.0.0 - 3.20.3 and 4.0.0 - 4.9.1. | 1.0.0 - 1.28.12.0.0 - 2.0.53.0.0 - 3.20.3 +1 more | Medium |
CVE-2021-29443 jose is vulnerable to Observable Discrepancy in versions 1.0.0 - 1.28.1, 2.0.0 - 2.0.5 and 3.0.0 - 3.11.4. | 1.0.0 - 1.28.12.0.0 - 2.0.53.0.0 - 3.11.4 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant